2026 CVE Vulnerabilities
44,815 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45628 | CRITICAL | 9.6 | 0.2% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.2 and earlier, Dokploy constructs shell commands ... |
| CVE-2026-45625 | CRITICAL | 9.9 | 0.4% | May 29, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, Arcane's huma-bas... |
| CVE-2026-48501 | CRITICAL | 9.1 | 0.3% | May 29, 2026 | GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.93.0, GitHub CLI incorrectly includes authorization h... |
| CVE-2026-45663 | CRITICAL | 9.9 | 0.9% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability ... |
| CVE-2026-44962 | CRITICAL | 9.9 | 0.7% | May 29, 2026 | Plesk contains an XPath injection vulnerability in the APS Application Catalog search functionality, where user-supplied... |
| CVE-2026-10064 | CRITICAL | 9.8 | 0.4% | May 29, 2026 | A security flaw has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file ... |
| CVE-2026-4290 | CRITICAL | 9.1 | 0.3% | May 29, 2026 | The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-gui... |
| CVE-2026-10063 | CRITICAL | 9.8 | 0.9% | May 29, 2026 | A vulnerability was identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the fil... |
| CVE-2026-10062 | CRITICAL | 9.8 | 0.8% | May 29, 2026 | A vulnerability was determined in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRou... |
| CVE-2026-10042 | CRITICAL | 9.8 | 0.6% | May 29, 2026 | manga-image-translator contains a remote code execution vulnerability in the shared API server mode due to unsafe deseri... |
| CVE-2026-46376 | CRITICAL | 9.8 | 0.4% | May 29, 2026 | FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access... |
| CVE-2026-10061 | CRITICAL | 9.8 | 5.0% | May 29, 2026 | A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. ... |
| CVE-2026-10060 | CRITICAL | 9.8 | 5.0% | May 29, 2026 | A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /gofor... |
| CVE-2026-9508 | CRITICAL | 10 | 0.3% | May 29, 2026 | Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow bac... |
| CVE-2026-8326 | CRITICAL | 10 | 0.4% | May 29, 2026 | Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitra... |
| CVE-2026-45312 | CRITICAL | 9.9 | 0.3% | May 29, 2026 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injectio... |
| CVE-2026-45043 | CRITICAL | 9.3 | 0.2% | May 29, 2026 | RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rust... |
| CVE-2026-10071 | CRITICAL | 9.8 | 0.5% | May 29, 2026 | DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers ... |
| CVE-2026-9559 | CRITICAL | 9.9 | 0.6% | May 29, 2026 | A path traversal vulnerability exists in the campaign import feature of Mautic 7. When extracting uploaded ZIP files dur... |
| CVE-2026-9558 | CRITICAL | 9.9 | 0.4% | May 29, 2026 | A Server-Side Template Injection (SSTI) vulnerability exists in Mautic's theme engine. The platform renders uploaded Twi... |
| CVE-2026-49201 | CRITICAL | 9.8 | 0.3% | May 29, 2026 | The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES encryption key. This allows a... |
| CVE-2026-49200 | CRITICAL | 9.8 | 0.5% | May 29, 2026 | The acer_cgi.log file in the device firmware is accessible without authentication via the web interface. This file conta... |
| CVE-2026-49199 | CRITICAL | 9.8 | 1.3% | May 29, 2026 | Crafted MQTT messages can trigger command injection, resulting in root-level code execution on the target device. |
| CVE-2026-49197 | CRITICAL | 9.8 | 0.3% | May 29, 2026 | Web endpoints intended for the Acer Connect app improperly validate the HTTP Authorization header, failing to block requ... |
| CVE-2026-3655 | CRITICAL | 9.8 | 0.5% | May 29, 2026 | The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in version... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now